About a month ago I decided to quit OTRS. I had my account removed.
When I try to login I get this nice message, so far so good:
Login error This account has been closed, most likely due to inactivity. Inactive accounts are routinely closed to maintain the security of the OTRS system/wiki and to make sure that only those who need access have it. If you require further information, or would like to discuss having your account re-activated, contact an OTRS administrator through their individual talk pages/e-mails or by writing an e-mail to volunteers-otrs [at] wikimedia [dot] org.
But I still had a logged in session and in that session I can still see all the private information on https://otrs-wiki.wikimedia.org . This is an information leak. Closed down accounts shouldn't be able to see anything anymore.
Judging from https://otrs-wiki.wikimedia.org/wiki/Special:ListGroupRights the group "Inactive users" was created for this, but if you compare https://otrs-wiki.wikimedia.org/w/index.php?title=Special:ListUsers&group=inactive to https://otrs-wiki.wikimedia.org/wiki/List_of_accounts/closed than you'll notice that lot's of users are not in there. https://otrs-wiki.wikimedia.org/w/index.php?title=Special:ListUsers&offset=&limit=5000&username=&group= gives an even better overview.
My guess is to fix this, all blocked accounts should be placed in the inactive user group. Probably a regular check should be performed to see if the blocked and inactive users are still in sync.
This problem might exist on other private wiki's.